CVE-2009-1586
GrabIt < 1.7.2 Beta 3 - Stack-Based Buffer Overflow via NZB File DTD Reference
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2009-1586. PoCs published by Jeremy Brown, Gaurav Baruah.
AI-analyzed exploit summary This exploit targets a stack-based buffer overflow in GrabIt 1.7.2x via a malformed NZB file, leveraging SEH overwrite with a custom ROP chain and shellcode to achieve remote code execution.
Description
Stack-based buffer overflow in the NZB importer feature in GrabIt 1.7.2 Beta 3 and earlier allows remote attackers to execute arbitrary code via a crafted DTD reference in a DOCTYPE element in an NZB file.
Exploits (2)
This exploit targets a stack-based buffer overflow in GrabIt 1.7.2x via a malformed NZB file, leveraging SEH overwrite with a custom ROP chain and shellcode to achieve remote code execution.
This exploit targets a SEH overwrite vulnerability in Grabit <= 1.7.2 Beta 3 via a malformed .nzb file. It uses a crafted XML header followed by a buffer overflow payload to achieve remote code execution.